See every DNS lookup before it becomes an incident.

FirstLayer by SecRange Solutions captures DNS at the wire, ties each query to a client and identity, and scores it against threat intelligence, all on your own infrastructure.

FirstLayer command deck

DNS is where attacks start and where most tools stop looking.

Login pages, API calls, malware callbacks and exfiltration tunnels all begin with a lookup, yet most stacks treat DNS as plumbing.

91%of malware uses DNS to operate
79%of organisations lack real-time DNS visibility
277 daysmean time to identify a breach

Tour the platform, screen by screen.

Eleven live views of the FirstLayer console. Pick one to see what it does.

One screen for situational awareness

A 360° radar of live DNS threats, a target computer with risk score and one-click Block, and a geo hub of destination countries and ASNs.

FirstLayer Command deck screen

From raw packet to a blocked threat in six steps.

Every feed you add runs through the same automated pipeline, with no analyst in the loop until an alert needs a decision.

Normalise

Lowercase IOCs, strip trailing dots, standardise feed formats.

Deduplicate

Merge repeats across feeds, keep the highest confidence.

Correlate

Match live DNS by direct, subdomain and resolved-IP strategies.

Generate matches

Attach feed, confidence, malware family and the matching log entry.

Score risk

Rate each match High, Medium or Low from confidence and history.

Alert and enforce

Store in ClickHouse, push live alerts, block with one call.

Rust

Collector

100K+ packets per second on commodity hardware.

Spring Boot

Threat engine and API

30+ endpoints for forensics, phishing, geo-IP, CDN and WHOIS.

ClickHouse

Analytics store

Billions of DNS rows with sub-second time-range queries.

React + Vite

Dashboard

WebSocket-driven, 14 panels, light and dark themes.

Built for teams that cannot afford a DNS blind spot.

Deploy with Docker Compose in your own environment and judge FirstLayer on live traffic during a pilot.

Banks and financial services

Meet PCI-DSS, SOX and GDPR logging needs and keep DNS data on your own servers.

Government and defence

Run fully air-gapped, with DNS tunnelling, DGA and Tor visibility.

Healthcare

Keep HIPAA audit trails and spot ransomware C2 without a costly SIEM add-on.

Mid-market enterprise

Get real DNS visibility without staffing a dedicated SOC tier.

Run FirstLayer on your own DNS traffic.

Tell us about your network and we will arrange a live demo and a pilot with the SecRange Solutions team.